CPCInsider

Analytics & CRM

GA4 audit checklist: 18 checks before you trust your reports

A hands-on GA4 audit for website owners and marketing teams: verify what is collected, trace real customer actions and separate tracking faults from reporting differences.

Vladlens Kecko · · 7 min read

Editorial illustration: Check the data. Trust the decision.

A GA4 audit checklist should verify the journey from a real customer action to the report used to make a decision. Seeing visitors in Realtime only proves that some data is arriving. It does not prove that purchases, enquiries or campaign sources are recorded correctly.

This guide covers a website implementation. Start with read access to GA4, access to your tag setup and test access to the website. Compare analytics with order or CRM records, and agree who can publish tracking changes. Record the property, stream, test device, consent choice and time of each test.

For a focused comparison, follow the GA4 and Google Ads reconciliation guide. Use the UTM naming template to standardise incoming campaign links.

The 18-point GA4 audit checklist

Use pass, fail or investigate for each row. Keep a screenshot or test log, an owner and a next action. An audit should leave a reproducible explanation, not just a list of settings.

CheckWhat to verify
1. OwnershipThe business retains appropriate access and former partners no longer have unnecessary access
2. Property and streamProduction traffic goes to the intended property and web stream
3. Currency and time zoneReporting settings match the business context used for comparison
4. Tag coverageImportant landing, product, checkout and confirmation pages send expected events
5. Duplicate installationA CMS plugin, hard-coded tag and GTM do not send the same event twice
6. Page viewsInitial loads and client-side navigation produce the intended page-view sequence
7. Event definitionsEach event has a clear business meaning and a documented trigger
8. Successful actionsA completed form or purchase triggers the intended outcome, not just a button click
9. Repeat actionsRefreshing, going back or retrying does not inflate successful outcomes
10. Key eventsImportant business outcomes are marked intentionally; engagement events are distinguishable
11. Ecommerce parametersPurchase IDs, value, currency and items match the test order
12. Consent statesDefault and updated consent states behave as designed for accept and reject choices
13. Personal dataURLs, titles and ordinary event parameters do not expose emails, names or phone numbers
14. Cross-domain journeysMoving to a controlled checkout or booking domain preserves the intended measurement
15. Unwanted referralsPayment or operational domains do not incorrectly claim acquisition credit
16. Internal traffic filtersExclusions identify the intended traffic without removing customers
17. Campaign attributionCampaign naming, redirects and linked advertising accounts preserve usable source data
18. ReconciliationDifferences from CRM and order records have an explained scope, delay and definition

Test one journey at a time

Enable debug mode for your test device with Tag Assistant or Tag Manager preview, then inspect the event sequence and parameters in GA4 DebugView. Use acquisition reports for attribution analysis; DebugView is primarily an implementation diagnostic.

Run these scenarios on desktop and mobile:

  • Visit a landing page, follow an internal link and confirm the expected page sequence.
  • Attempt an invalid form submission; confirm it is not recorded as a successful enquiry.
  • Submit a valid form and match the event with the received CRM or inbox record.
  • Reload the confirmation screen and check whether the success event repeats.
  • For a shop, complete a test purchase, inspect its parameters and compare it with the order system.

Avoid concluding that an event is missing solely because the debug panel is empty. Check the selected device, debug setup, consent state and network requests. A blocked or unconsented journey can behave differently from your accepted-consent test.

Diagnose duplicates before changing reports

List every route by which an event can be sent: site code, a CMS plugin, GTM or a server integration. Look for two senders or a trigger that fires on both a click and a success callback. Fix the sender or trigger rather than trying to hide duplicate activity in a report.

For ecommerce, validate recommended event names and required fields against Google’s ecommerce implementation guide. Use a unique transaction ID for each order and test refresh behaviour. Google’s validation guide explains transaction-ID handling; do not assume the same protection applies to every custom lead event.

A GA4 audit discussion on Reddit highlights checking event firing against real user actions before trusting reports. This is anecdotal advice; the reproducible journey and official implementation reference are what establish whether your setup works.

Test a new visitor who accepts, one who rejects and a returning visitor who changes their choice. Use Google’s consent debugging procedure to inspect defaults, updates and tag behaviour. A visible banner alone does not establish correct consent signalling.

Inspect URLs and payloads after form submissions. Keep email addresses, phone numbers and names out of ordinary analytics parameters, page titles and URLs. See Google’s PII guidance. Treat purpose-built user-data features as a separate implementation, rather than putting customer details in arbitrary fields.

Repair source attribution without hiding the problem

If you control multiple domains in one customer journey, check the cross-domain configuration and whether redirects preserve the linker parameter. For a payment-provider return, inspect unwanted referral settings. These settings solve different problems; excluding a referral is not a substitute for a correctly connected journey.

Check campaign links from the actual email or advertisement, including any redirect. Use consistent campaign naming on incoming marketing links. Avoid adding campaign tags to ordinary internal navigation, which can make interpretation harder.

Test internal and developer filters before activating them. Google notes that excluded data is permanently unavailable, and filters do not repair historical data. Document the activation date so later report changes have an explanation.

Reconcile a sample, then prioritise fixes

Compare a clearly defined period after data has had time to process. Align time zones, currency, event definitions and attribution scope. GA4, Google Ads and your CRM answer different questions; identical totals are not automatically the correct target.

An illustrative finding might be 10 accepted test enquiries in the CRM but 20 success events because both a click handler and a confirmation-page trigger fire. That gives you a specific implementation fix. A difference caused by consent choices or attribution windows needs an explanation, not an invented balancing event.

Prioritise exposed personal data, missing or duplicate business outcomes and broken customer-source continuity. Then improve naming and report usability. If these events feed advertising decisions, also check the Google Ads audit checklist and your CRM integration.

Common questions

Is Realtime enough for an audit?

No. Combine a controlled journey, event parameters, debug tools and processed reporting. Confirm business outcomes against the system that actually receives the order or enquiry.

Should every event be a key event?

Choose events that represent important business outcomes. Keep supporting engagement actions separately interpretable. Check Google Ads conversion goals independently before using imported events for bidding.

Will fixing tracking repair old reports?

Most implementation fixes change future collection. Annotate the correction date and avoid comparing before and after as if the measurement method had always been identical.

Find the tracking issues that affect your decisions

Request a free performance audit and mention GA4 tracking in your enquiry. We can review your measurement priorities and discuss the next steps. For implementation support, explore tracking, attribution and CRM.

About the author

Vladlens Kecko

Continue reading

Related services and proof

Tracking, Attribution & CRMPaid Media Growth4,002 qualified leads connected to €818,681 in revenue